Privacy Policy
Effective as of September 3, 2026.
California Notice at Collection and State Privacy Rights notice: see the State privacy rights section below for the categories of personal information we collect, the purposes we collect them for, how long we keep them, and the rights you have.
Root System LLC ("Root System", "we", "us" or "our") operates rootsystem.com and forensics.rootsystem.com (together, the "Sites"). Root System Forensics is the technical-analysis and expert-witness practice operated by Root System LLC. This Privacy Policy describes how we handle personal information collected through the Sites and through email you send to the addresses published on them.
The Sites are business-to-business. They are not directed at consumers acting for personal, family or household purposes, and nothing on them is sold to individuals.
Personal information we collect
Information you provide to us.
- Contact data
- Your name, your email address, and — on the case intake form — the firm or company you are writing on behalf of.
- Enquiry content
- The message you write in the contact form on rootsystem.com.
- Case intake data
- On the intake form at forensics.rootsystem.com: the type of engagement you are asking about, a free-text description of the matter, your timing, and how you heard about the practice.
- Email correspondence
- Anything you send to the addresses published on the Sites, and our replies.
A note about the free-text fields, because the intake form asks you to describe a live matter. The intake form is a screening step. Submitting it does not create an attorney–client relationship, an expert engagement, or any duty of confidentiality, and the form is not a secure channel. Please do not send privileged material, client-identifying detail, or anything under a protective order through it. A non-disclosure agreement is executed before any confidential material moves; describe the matter at the level you would describe it to someone you had not yet retained.
Information collected automatically.
- Device and connection data
- When you submit a form we record the browser user-agent string and the country our hosting provider derives from your IP address. We do not store your IP address in our own records; our hosting provider logs it as part of delivering and protecting the Sites.
- Usage data
- On forensics.rootsystem.com only, we record a small, fixed set of events: which pages were viewed, whether the rate card was opened, whether an expandable section was opened, and whether the intake form was started and submitted. There is no session recording and no automatic capture of clicks, keystrokes or form contents. rootsystem.com has no analytics of any kind.
- Anti-spam data
- Our forms carry a hidden field that human visitors never fill in and a Cloudflare Turnstile challenge. When a submission is judged automated we record that verdict, the challenge error codes, and a copy of the hidden field truncated to 100 characters, so that we can see what the forms are receiving.
Cookies and similar technologies
The Sites set no cookies, and there is no consent banner because there is nothing to consent to.
forensics.rootsystem.com stores one anonymous identifier in your browser’s sessionStorage, which your browser discards when you close the tab. Its only purpose is to join the pages of a single visit together. It does not persist between visits and cannot identify you.
Cloudflare Turnstile, which protects the forms from automated submission, may store data in your browser for that purpose. It is a security control, not an analytics or advertising technology.
How we use personal information
- To respond to your enquiry, and to reply within the response time the Sites publish.
- To run a conflict check, against our record of past enquiries and current engagements.
- To scope, price and deliver an engagement, and to administer it.
- To operate and secure the Sites, including detecting and blocking automated and abusive submissions.
- To understand, in aggregate, how the forensics site is used.
- To comply with law, and to establish, exercise or defend legal claims.
We do not use your personal information for advertising, and we do not use it to train machine-learning models, our own or anyone else’s.
How long we keep personal information
- Case intake — the matter description
- We delete the free-text description of the matter 90 days after it is submitted. There is no exception to this. Where a matter goes on to become an engagement, the matter record is held in a separate system, not in the one that receives the form.
- Case intake — the conflict record
- We keep your name, email address, the domain of the address you write from, the firm name if you give one, the engagement type and the date for as long as we operate the practice, so that we can check conflicts against new matters.
- Engaged matters
- Where an engagement follows, the records of that engagement are held separately from the intake form and retained for as long as our legal, professional and insurance obligations require, which is longer than any period above.
- Contact enquiries
- Messages sent through the contact form on rootsystem.com are deleted twelve months after they were received.
- Submissions judged automated
- Kept in the form the spam controls recorded them, so the controls themselves can be reviewed, and deleted on the same twelve-month schedule.
- Usage data
- Retained by our analytics provider under its own retention schedule. It is not joined to a form submission and does not identify you.
Security
The Sites are served over HTTPS and submissions are transmitted encrypted. Stored submissions sit in a managed database with access limited to the people who operate the practice. We use technical, organizational and physical safeguards designed to protect personal information, but security risk is inherent in all internet and information technology and we cannot guarantee the security of your information.
Other sites and services
The Sites link to services operated by third parties. Those links are not an endorsement, we do not control those services, and this policy does not cover them. Read their privacy policies.
Where your information is processed
Root System LLC is based in the United States, and personal information you provide is processed there. Some of our service providers operate infrastructure in other countries, so your information may be processed in a location whose privacy laws differ from those of your own state or country.
Children
The Sites are not intended for anyone under 18, and we do not knowingly collect personal information from children. If you believe we have, contact us at the address below and we will comply with the applicable legal requirement to delete it.
State privacy rights
This section applies to residents of U.S. states whose privacy laws apply to us and grant the rights described here (the "State Privacy Laws"). Not every right is available to every resident, and these rights are not absolute — we may decline a request where the law permits.
Subject to those limits, you may ask us to:
- Confirm whether we process your personal information, and give you access to it.
- Provide a copy in a portable form.
- Correct inaccurate personal information.
- Delete personal information we hold about you.
- Tell you the categories of personal information we collect, the purposes we collect them for, and the categories of third parties we disclose them to. That information is in the table below and in the sections above.
- Appeal a decision we make on any of the above, where your state provides an appeal.
Sale, sharing and targeted advertising. We do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not use it for targeted advertising. There is accordingly no opt-out to offer you. We recognize the Global Privacy Control ("GPC") as a valid opt-out preference signal; because we do not sell or share, receiving one changes nothing about how we handle your information.
Sensitive personal information. We do not ask for sensitive personal information and do not use any for the purpose of inferring characteristics about you. The intake form has a free-text field, so a submission may contain categories of information we did not request; we treat what arrives there according to this policy and delete it on the schedule above.
Consumers under 16. We have no actual knowledge that we collect, sell or share the personal information of consumers under 16 years of age.
Non-discrimination. You may exercise these rights free from discrimination, as the State Privacy Laws require.
Making a request. Email contact@rootsystem.com with the request you want to make. We do not operate a request webform or a phone line.
Verifying a request. We will ordinarily verify you by asking you to write from the email address used to submit the form, or by asking for detail that matches a record we hold. We will not ask for government identification unless we cannot verify a request any other way, and we will not use anything you send for verification for any other purpose.
Authorized agents. You may use an authorized agent where your state allows it. We may ask for a copy of a power of attorney, or for your written and signed permission plus direct confirmation from you, before we act on the request.
| Personal information we collect | CCPA statutory category | Purposes | Disclosed for a business purpose to | Sold or shared |
|---|---|---|---|---|
| Contact data: name, email address, the domain of that address, firm or company | Identifiers; professional or employment-related information | Responding to enquiries; conflict checks; scoping and delivering an engagement; security | Service providers (hosting and database, email delivery); professional advisers | None |
| Enquiry and case intake content: your message, engagement type, matter description, timing, referral source | Identifiers; commercial information; and any category you choose to include in a free-text field | Responding to enquiries; conflict checks; scoping and delivering an engagement | Service providers (hosting and database, email delivery); professional advisers where a conflict check or legal obligation requires it | None |
| Device and connection data: browser user-agent string, country derived from IP address | Internet or other electronic network activity information; geolocation data, at country level only | Security and spam prevention; distinguishing genuine enquiries from automated ones | Service providers (hosting, bot mitigation) | None |
| Usage data from forensics.rootsystem.com: declared page and interaction events, session-scoped anonymous identifier | Internet or other electronic network activity information | Measuring how the site is used | Service provider (product analytics) | None |
Shine the Light. California Civil Code § 1798.83 lets California residents ask whether a business has disclosed their personal information to third parties for those third parties’ own direct marketing. We do not make such disclosures. If you would like that confirmed in writing, email contact@rootsystem.com with the subject line "Shine the Light Request", your first and last name, your mailing address, and a statement that you are a California resident.
Changes to this policy
We may modify this Privacy Policy. If we make a material change we will update the effective date above and post the revised policy here. Your use of the Sites after that date indicates that the revised policy applies.
How to contact us
Root System LLC — contact@rootsystem.com. Write to that address for a privacy request, a question about this policy, or a correction to anything in it.